A security incident response team is investigating a potential breach involving an unauthorized highly privileged account in the cloud management plane. The team needs to quickly understand all actions performed by this account, including resource creation, modification, and deletion across various cloud services. Which of the following cloud infrastructure components provides the MOST granular and centralized record of these management plane activities?
- AOperating system event logs from individual VMs.
- BCloud provider's API activity logs (e.g., CloudTrail, Activity Logs).
- CApplication-level audit logs from deployed services.
- DNetwork flow logs (e.g., VPC Flow Logs).
Show answer & explanationAnswer & explanation
Correct answer: B. Cloud provider's API activity logs (e.g., CloudTrail, Activity Logs).
Cloud provider's API activity logs (like AWS CloudTrail, Azure Activity Logs, or GCP Cloud Audit Logs) are specifically designed to record all API calls made to the cloud management plane. These logs provide a centralized, granular, and immutable record of who did what, when, and from where, across all integrated cloud services, making them invaluable for investigating management plane breaches.
Why the other options are wrong
- A. OS event logs from VMs record activities within the guest operating system but do not show actions performed via the cloud management plane API (e.g., creating a VM, deleting a database).
- C. Application-level audit logs record events within a specific application but do not capture actions performed directly against the underlying cloud infrastructure via the management plane.
- D. Network flow logs record network traffic metadata (source/destination IP, port, protocol) but do not record API calls or administrative actions on cloud resources.
Cloud API Activity Logs
Logs that capture all API calls and administrative actions made to a cloud provider's management plane, providing an audit trail for security and operational purposes.
- Records 'who, what, when, where' for management plane actions.
- Crucial for security investigations and compliance.
- Examples: AWS CloudTrail, Azure Activity Logs, GCP Cloud Audit Logs.
Memory trick: API logs capture every cloud command, clear evidence for the investigation at hand.